Daily briefing · July 5, 2026
cve-search Critical Flaw Leads July 5 Roundup Alongside Multiple PoC-Exposed Vulnerabilities
July 5, 2026 brought 84 new vulnerabilities, with one critical disclosure standing out: an unauthenticated input validation flaw in cve-search that could expose administrative credentials directly from MongoDB. The day saw no active KEV exploitation, but six of the ten highlighted CVEs carry public proof-of-concept code, significantly narrowing the window between disclosure and real-world abuse. Several entries target Turkish public-sector software from TUBITAK BILGEM, broadening the geographic scope of concern.
Today’s brief
- CRITICAL: CVE-2026-59509 in cve-search allows unauthenticated attackers to read MongoDB collections, including admin password hashes — patch or isolate immediately.
- Six of ten highlighted CVEs have public PoC exploits, meaning weaponization is already within reach of low-skilled attackers.
- Multiple TUBITAK BILGEM products (Pardus suite, Domain Joiner) are affected by privilege escalation, DNS spoofing, and credential exposure flaws.
- Network devices and web applications (UTT HiPER router, Ruijie RG-UAC, WeChat bot) round out a diverse and practically exploitable set of targets.
1
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
An unauthenticated attacker can manipulate POST parameters on the /fetch_cve_data endpoint to query arbitrary MongoDB collections in cve-search, including the mgmt_users collection containing admin usernames and password hashes. With a public PoC already available, any exposed instance should be treated as compromised until patched or isolated.
2
Incorrect permission assignment in Pardus-Parental-Control (versions up to 0.5.1) allows attackers to perform DNS spoofing, potentially redirecting users to malicious infrastructure. Organizations running this parental control solution on Turkish Pardus Linux deployments should upgrade to 0.7.0 or later without delay.
3
A stack-based buffer overflow in the UTT HiPER 1250GW router's web endpoint (via the ssid argument) can be triggered remotely, and a public exploit has already been disclosed. Routers exposed to the internet or untrusted networks are at direct risk of remote code execution.
4
Pardus Domain Joiner (before 0.5.4) exposes sensitive credentials through process invocation in a way visible to local observers, enabling credential excavation by low-privileged users. Systems joined to domains using this tool should be updated and credentials rotated as a precaution.
5
A missing authorization check in Pardus Update (before 0.6.6) can be leveraged for local privilege escalation, allowing an attacker with limited access to gain elevated system rights. This is especially concerning in multi-user or shared environments running the Pardus Linux distribution.
6
A path traversal vulnerability in AIL Framework's PDF object handling allows authenticated users to read files outside the intended PDF storage directory. Defenders should apply the fix from commit 14c618fce4d1df02358717c48ea903706abecdf2 and audit file access logs for anomalous path patterns.
7
Missing authentication on the wx endpoint's verify_server function in chatgpt-on-wechat CowAgent 2.1.0 allows remote attackers to interact with the WeChat integration without credentials, with a public PoC already available. Instances exposed to the internet should be upgraded or placed behind authentication controls immediately.
8
An unrestricted file upload vulnerability in Ruijie RG-UAC's user_auth_commit.php allows remote attackers to upload arbitrary files, a classic vector for webshell deployment and full system compromise. The public exploit makes this an urgent patching priority for any organization using this unified access controller.
9
SQL injection via the street, city, and status parameters in the Smart Parking System 1.0 (/parkings/parkings.php) can be exploited remotely to extract or manipulate the underlying database. A public exploit is available, making any publicly accessible deployment an easy target for data theft.
10
A SQL injection flaw in SourceCodester Class and Exam Timetabling System 1.0 (/edit_product.php) via the ID parameter allows remote attackers to interact with the backend database. With a published exploit, educational institutions running this system should restrict access and apply available patches immediately.
Today’s recommendation: Prioritize patching or network-isolating CVE-2026-59509 in any cve-search deployment, as unauthenticated credential theft poses an immediate takeover risk; simultaneously audit all PoC-exposed entries (especially CVE-2026-14721, CVE-2026-14736, and CVE-2026-14735) and apply vendor updates or compensating controls before attackers operationalize the available exploits.
With six public exploits disclosed in a single day spanning routers, web apps, and platform tools, now is the right moment to validate which of these affected components actually exist in your environment and confirm your detection coverage can catch exploitation attempts.Find out in minutes, with a free exposure assessment, where your organization is truly exposed.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →